AMLBot confirmed the Polymarket supply-chain attack total at about $3.1 million in PUSD across 11 user wallets. The supplied event summary says the funds were bridged from Polygon to Ethereum and converted to ETH. Polymarket has pledged full refunds, but the compromised vendor has not been named in the supplied material.

Primary sourceTheDefiant
Reported at2026-06-27T17:13:43.000Z
TopicETH
Evidence limitReported facts are separated from interpretation; current prices and platform terms require independent verification.
Official platform access

Evaluate OKX for your use case

Check regional eligibility, current fees and product availability on the official destination.

Review OKX
01

Direct Answer

AMLBot put the Polymarket phishing toll at approximately $3.1 million in PUSD across 11 user wallets. The funds were reportedly bridged from Polygon to Ethereum and converted to ETH.

The incident is framed as a supply-chain attack in the supplied event summary. Polymarket has pledged full refunds, but the summary does not identify the compromised vendor.

02

Why It Matters

The key issue is not just the dollar amount. The reported movement from Polygon to Ethereum means affected users and observers should separate the original wallet compromise from the later movement and conversion of funds.

ETH and MATIC are both relevant to the event because the supplied brief lists ETH and MATIC as affected assets, and the described fund path crosses Polygon and Ethereum. That does not by itself prove broader risk to either network or support a trading conclusion.

03

Evidence Limits

This article uses only the supplied event summary and brief. It does not add wallet addresses, vendor identity, refund timing, investigation status, law-enforcement claims, or recovery details not provided in the source material.

The supplied material attributes the report to TheDefiant and says AMLBot confirmed the approximate total. No independent ranking, traffic, indexing, registration, or outcome claim is made here.

04

Practical Checks

Users who interacted with Polymarket or related wallet prompts should review recent wallet activity, signed approvals, bridge transactions, and unexpected token movements. Any suspicious approval should be handled cautiously before further wallet use.

A practical response is to keep higher-value funds separate from active trading or app-interaction wallets, verify domains and prompts before signing, and avoid treating a refund pledge as a substitute for checking wallet exposure.

05

Risk Disclosure

This is a security incident summary, not financial advice. The fact that funds were converted to ETH does not establish a price outlook for ETH, MATIC, PUSD, or any related asset.

Supply-chain incidents can create confusion because the visible wallet transaction may be only one part of the compromise. The supplied material does not identify the vendor, so readers should avoid naming or blaming parties beyond the confirmed summary.

06

OKX Context

For readers who use OKX or follow ETH and MATIC markets through OKX, this story is best treated as operational risk context rather than a buy or sell signal.

If a reader decides independently to open or use an OKX account, they should review the official signup terms, regional eligibility, fee details, and any code information on the destination page before acting. No reward, ranking, approval, or trading outcome is claimed here.

Official platform access

Evaluate OKX for your use case

Check regional eligibility, current fees and product availability on the official destination.

Review OKXAffiliate link · Availability varies by region · No guaranteed outcome
FAQ

Questions readers ask

What happened in the Polymarket phishing incident?

AMLBot confirmed a Polymarket supply-chain attack total of about $3.1 million in PUSD across 11 user wallets, according to the supplied event summary.

Where did the funds go after the reported attack?

The supplied summary says the funds were bridged from Polygon to Ethereum and converted to ETH.

Has Polymarket named the compromised vendor?

No. The supplied material says Polymarket has not named the compromised vendor.

Did Polymarket promise refunds?

Yes. The supplied event summary says Polymarket pledged full refunds, but it does not provide refund timing or completion details.

Does this mean ETH or MATIC prices will move?

No trading conclusion is supported by the supplied material. The incident is a security and fund-tracing story, not a financial recommendation.

Independent educational content. Last updated 2026-07-22. This page is not investment, legal or tax advice.